code16/sharp Security Advisories for v9.20.0 (2)
-
[MEDIUM] Sharp Missing Authorization Check in Quick Creation Command Endpoints
PKSA-krdf-j5zz-ky6v CVE-2026-53634 GHSA-vmwx-m75v-qvch
Affected version: >=9.0.0,<9.22.3
Reported by:
GitHub -
[HIGH] Authenticated Sharp users can download unrelated Laravel Storage objects through the generic download endpoint
PKSA-h9kt-ss6k-xq4z CVE-2026-44692 GHSA-748w-hm6r-qc7v
Affected version: <9.22.0
Reported by:
GitHub